Junglewise Threat Intelligence

CVE-2026-28993: Apple Multiple Operating Systems sensitive data access via missing consent prompt

CVE-2026-28993 · Severity: medium · CVSS 5.5 · Published 2026-05-11

Technologies: Apple Visionos, Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability in Apple operating systems could allow a third-party application to access sensitive user information without proper authorization. This could lead to the exposure of private data stored on the device. Apple has addressed this by requiring an additional prompt for user consent before such data can be accessed.

Technical details

A privacy vulnerability existed in multiple Apple operating systems where an application could bypass intended data access restrictions to retrieve sensitive user information. The root cause was a lack of sufficient user consent verification for certain data access requests. An attacker could exploit this by developing a malicious app that, once installed, accesses private data without the user's knowledge. Apple addressed the issue by adding an additional prompt for user consent and improving state management. Patches are available in iOS 18.7.9/26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, and visionOS 26.5.

Affected products

  • Apple iOS Before 18.7.9, before 26.5
  • Apple iPadOS Before 18.7.9, before 26.5
  • Apple macOS Sequoia Before 15.7.7
  • Apple macOS Sonoma Before 14.8.7
  • Apple macOS Tahoe Before 26.5
  • Apple visionOS Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats